2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6373CRITICAL9.8A vulnerability has been found in itsourcecode Online Food Ordering System up to 1.0 and classified as critical. This vu...
CVE-2024-6372CRITICAL9.8A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affec...
CVE-2024-6371CRITICAL9.8A vulnerability, which was classified as critical, has been found in itsourcecode Pool of Bethesda Online Reservation Sy...
CVE-2024-38515Rejected reason: This CVE is a duplicate of CVE-2024-38374.
CVE-2024-1107CRITICAL9.8Authorization Bypass Through User-Controlled Key vulnerability in Talya Informatics Travel APPS allows Exploiting Incorr...
CVE-2024-6370MEDIUM5.4A vulnerability classified as problematic was found in LabVantage LIMS 2017. Affected by this vulnerability is an unknow...
CVE-2024-6369MEDIUM5.4A vulnerability classified as problematic has been found in LabVantage LIMS 2017. Affected is an unknown function of the...
CVE-2024-6368MEDIUM5.4A vulnerability was found in LabVantage LIMS 2017. It has been rated as problematic. This issue affects some unknown pro...
CVE-2024-6367MEDIUM5.4A vulnerability was found in LabVantage LIMS 2017. It has been declared as problematic. This vulnerability affects unkno...
CVE-2024-6262MEDIUM6.4The Portfolio Gallery – Image Gallery Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p...
CVE-2024-5535CRITICAL9.1Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer ma...
CVE-2024-0949CRITICAL9.8Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability...
CVE-2024-0947CRITICAL9.8Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Sessi...
CVE-2024-4983MEDIUM5.4The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2024-5601MEDIUM5.4The Create by Mediavine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Schema Meta s...
CVE-2024-22232HIGH7.7A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user ca...
CVE-2024-22231MEDIUM5Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious...
CVE-2024-4704MEDIUM6.1The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and...
CVE-2024-4664MEDIUM4.8The WP Chat App WordPress plugin before 3.6.5 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-3111MEDIUM5.4The Interactive Content WordPress plugin before 1.15.8 does not validate uploads which could allow a Contributors and a...
CVE-2024-1330MEDIUM4.3The kadence-blocks-pro WordPress plugin before 2.3.8 does not prevent users with at least the contributor role using som...
CVE-2024-6283MEDIUM5.4The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL parameter of ...
CVE-2024-4570MEDIUM5.4The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter i...
CVE-2024-4569MEDIUM5.4The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter i...
CVE-2024-6054HIGH8.8The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now